AiTM phishing can turn a routine vendor request into a live browser hijack, letting attackers reuse an authenticated Microsoft 365 session even after MFA is completed.
A reported campaign using Besomar-themed decoys shows how defense procurement workflows can be turned into an entry point, even when the payload chain is still only partly visible.
A procurement-themed lure and a JavaScript payload are being used to probe US enterprises, with the malware described as a backdoor that seeks persistent access.